Suspicious PDQDeployRunner Execution on Windows with Encoded/Download Indicators

Alerts on child process activity from PDQDeployRunner parents showing encoded, hidden, or download-related command line indicators.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-22
Updated
2026-07-30

What it detects

This rule flags process creation where the parent process image contains the PDQDeployRunner naming pattern and the spawned child process matches specific suspicious execution indicators. It matters because PDQDeployRunner can be abused to execute remote commands, including PowerShell-style encoded or hidden download/decode behavior. The detection relies on Windows process creation telemetry, specifically the parent image, child image name/path, and child command line substrings such as -enc/-encodedcommand and web/download/decode functions.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.